Hacker News new | past | comments | ask | show | jobs | submit login
We used chatbot code from IBM, and it was instantly vulnerable to XSS attacks (github.com/ibm)
3 points by ftreml on Feb 2, 2021 | hide | past | favorite | 3 comments

The repo reads like research code, and indeed seems to be an article's companion code plus platform example code. The code in question was committed in 2018 and never touched again.

That's no excuse, it pretty literally does "innerhtml = user_input" and it's awful. But it's not a flagship chatbot library from what I see, which probably lessens the impact of such awfulness.

partially agree. In another repo, the same vulnerability was only fixed after years ...


I wrote about security threats for chatbots


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
